mnemonic security podcast

mnemonic security podcast

Download on the App Store

mnemonic security podcast episodes

  • Security of Things

    Security of things

    “IoT security today is like what IT security was in the early 90s”.

    This is how our returning guest introduces this episode’s topic; IoT security, and how it affects organisations and companies.

    For the third time, Robby is joined by Brian Contos, serial security entrepreneur and now Chief Security Officer at Phosphorus Cybersecurity, a company providing IoT and OT defense solutions for enterprise customers.

    Brian explains the meaning behind his not so uplifting statement above, and shares some of the most common IoT security issues they observe among their customers. He also discusses whether certain IoT devices pose a larger threat for organisations than others do, and why it’s so difficult for many organisations to create an inventory of their IoT devices.

    Sound engineering by Paul Jæger

    Send us Fan Mail

    40 min
  • The ransomware dilemma

    mnemonic, all government agencies and the majority of organisations in the security community advise against paying ransom to the criminal groups behind ransomware extortions. There are also legal considerations that need to be considered depending on the country or industry you are operating in. 

    There is however, a value in knowing more about how these criminal groups work. To shed some light on this, we’ve invited someone that often has been faced with the dilemma of whether or not to pay the ransom together with his clients; Rickey Gevers, Co-Founder of Responders B.V., a Dutch incident response company. These days most of the incidents he deals with are related to ransomware, and Rickey shares his experiences from negotiating with close to 30 ransomware groups on behalf of his clients – including also helping to pay them.

    He shares his advice for how to prevent and prepare against ransomware threats. As well as what concerns most of his clients have when deciding how to deal with these groups, the main challenges they meet when negotiating with them, and how negotiating with ransomware groups requires a different approach than traditional negotiating tactics.

    Sound production by Paul Jæger

    Send us Fan Mail

    36 min
  • Encrypted traffic management

    Encrypted traffic management

    TLS, SSL, HTTP,  keys, authentication, clients, servers and ciphers - encryption is complicated.

    To help shed some light on how enterprises can remove the "blind spot" of encrypted network communication, we’ve invited David Wells, co-founder of Netronome, who is a pioneer in the SSL/SSH inspection  space.

    David explains why being able to see and analyse encrypted traffic is necessary in order to gain full security value out of your network data, and shares his experiences since he inadvertently invented a tool for SSL inspection in 2003.

    Technical level: 4/5

    Sound engineering by Paul Jæger

    Send us Fan Mail

    35 min
  • Conti leaks - The inside of the dark side

    What can we actually learn about cybercrime and what really goes on inside of criminal organisations from the Conti leaks?

    This episode we welcome Sergey Shykevich,  who has more than a decade of experience within threat intelligence and defence. He’s currently leading the threat intelligence research group in Check Point, and Robby has invited him to share his findings after examining the data leaks from the predominantly Russian-based double extortion group Conti.

    The large data leak included more than 400 000 messages and access to internal forums providing information about everything from offices, bonuses and recruitment, to organisational structure, information flow, and whether or not members are aware of the fact that they’re working for a crime syndicate.

    Produced by Paul Jæger

    Send us Fan Mail

    38 min
  • The Science of SOAR
    The science of SOAR

    Is cybersecurity automation and orchestration actually complicating, instead of reducing, the human workload it is meant to relieve?

    Joining us, to discuss this and more, we have Dr. Vasileios Mavroeidis, Cybersecurity scientist at the University of Oslo, specialising in security automation and cyber threat intelligence representation, inference, and sharing.

    He explains how he defines cybersecurity automation, and what he sees as the opportunities but also the limitations when minimising human intervention in cybersecurity processes.

    Robby and Vasileios also discuss the importance of open standards and open source tools in this domain, and how automation differs in OT environments.

    Produced by Paul Jæger

    Send us Fan Mail

    30 min
  • Control Validation & Cyber Insurance

    Control Validation & Cyber Insurance

    How can private-sector cyber insurers accurately understand and price risk?

    To discuss this and the critical role insurance can play in risk mitigation strategy, we’re joined by Levi Gundert, Senior Vice President of Global Intelligence at the cybersecurity company Recorded Future.

    Levi shares from his vast experience from the industry, from previous roles as VP of Cyber Threat Intelligence at Fidelity Investments, Technical Leader at Cisco Talos, Principal Analyst at Team Cymru and US Secret Service Special Agent within the Los Angeles Electronic Crimes Task Force (ECTF).

    He’s joining the podcast to discuss his recent paper “A New Cyber Insurance Model: Continuous Control Validation”, analysing the current state of the cyber insurance market and providing a new framework for insurers to evaluate risk.

    Recommended reading: https://www.recordedfuture.com/new-cyber-insurance-model-continuous-control-validation/

     Produced by Paul Jæger

    Send us Fan Mail

    35 min
  • Special Edition: SOCCRATES

    For this episode, we’re welcoming Frank Fransen, Senior Scientist - Cyber Security, and Reinder Wolthuis, Senior Consultant and Program Manager - Cyber Security, from the Dutch not for profit research and consultancy organisation, TNO. 

    They joined Robby to talk about the SOCCRATES research project, where TNO, mnemonic and seven other European organisations are combining efforts to build a platform for security operations centres (SOCs) and incident response teams, to help them be more efficient, better detect attacks, and make the correct decisions on how to handle them. 

    The research project is part of the European Union's Horizon 2020 Research and Innovation program (https://www.soccrates.eu/), and aim is to produce a platform that will be as open-source as possible. 

    During their conversation, Frank and Reinder share why they saw the need for a platform like this, what it’s like to coordinate a project between public and private organisations, different expertise fields and across countries borders, and what the plan is for the upcoming pilot. 

    Produced by Paul Jæger

    Send us Fan Mail

    37 min
  • Space Norway

    What caused a nation like Norway to become amongst the first pioneers of satellite-based communications?

    To explore this, Robby is joined by Ronny Klavenes, CISO at Space Norway, a company building and investing in space related infrastructure, especially focusing on critical infrastructure. Space Norway was established on an initiative from The Norwegian Space Agency, a government agency promoting the development of national space activities. Among other things, Space Norway owns the underwater fibre optic cable between Svalbard and mainland Norway, a key element of Norway’s infrastructure in the Arctic.

    Ronny explains why Norway cares about space infrastructure, and how one approaches securing infrastructure like this. He also shares what their threat landscape look like, and how their technology can be used to among other things monitoring earthquakes and ice blocks detaching from glaciers, search and rescue services, as well as collaborations with SpaceX.

    Produced by Paul Jæger

    Send us Fan Mail

    33 min
  • Deception technology

    Deception technology

    Deception as an attack tactic has been used in many forms, for many years. Both on the battleground in the physical world, and in the digital sphere.

    For this episode on deception technology, Robby is joined by Ofer Israeli, Founder & CEO of Illusive, a cybersecurity company aiming to remove the vulnerable connections that enable attackers to move undetected, and replace them with deceptive versions that reveal the attacker’s presence.

    Ofer explains how he suggests moving away from a reactive mind-set to avoid always playing catch-up with attackers, how deception technology has evolved beyond honeypot-based approaches, and the importance of detection for this to succeed.

    Produced by Paul Jæger

    Send us Fan Mail

    31 min
  • Collecting and sharing threat intelligence

    How does one of the world’s largest cybersecurity companies collect and share their Threat Intelligence? 

    For this episode, Ryan Olson, Vice President of Threat Intelligence (Unit 42) at Palo Alto Networks, joins Robby for a chat about Palo Alto Networks’ telemetry pool and how Threat Intelligence has evolved over the last decade.

    His team, Unit 42, are responsible for collecting, analysing and producing intelligence for a large number of organisations worldwide, and Ryan shares what goes on in the Unit 42 team when an event like Log4shell occurs.

    He also looks back at the major trends they observed in 2021, and what new adversary techniques and potential attack paths interests him the most these days.

    Produced by Paul Jæger

    Send us Fan Mail

    36 min

About mnemonic security podcast

From the publisher's feed

Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across…

More shows like mnemonic security podcast

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

651 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Misjonen med Antonsen og Golden by P4-gruppen

Misjonen med Antonsen og Golden

84 Listeners

#pengepodden by Nordnet

#pengepodden

22 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

The Daily by The New York Times

The Daily

111,874 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Nasjonal sikkerhetsmyndighet (NSM) by Nasjonal sikkerhetsmyndighet (NSM)

Nasjonal sikkerhetsmyndighet (NSM)

1 Listeners

Nerdelandslaget by Nerdelandslaget // Acast

Nerdelandslaget

7 Listeners

MEDVIND by Alexis Barnekow

MEDVIND

0 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Prompt by DR

Prompt

3 Listeners

Only in America by RADIO IIII

Only in America

25 Listeners

Plattformpodden by Hans Kristian Flaatten og Audun Fauchald Strand

Plattformpodden

0 Listeners